High-level statements of what SFA must achieve to keep information secure; each policy sets the objectives that its supporting standards put into practice.
Sets SFA's objectives for governing the security program and protecting its people, vendors, data, and privacy, including awareness and training, acceptable use, AI governance, and research security; carried out by Standards 06-107.1.1 through 06-107.1.6.
Sets SFA's objectives for the technical safeguards that protect its systems, devices, and data, covering access, asset management, system development, continuity and disaster recovery, security monitoring, and incident response; carried out by Standards 06-107.2.1 through 06-107.2.6.
Sets SFA's objectives for protecting the facilities, equipment, and environmental controls that support its information systems; carried out by the Physical and Environmental Security Standard (06-107.3.1).
Sets SFA's objectives for identifying and managing the security and privacy risks introduced by vendors and third-party services, from pre-purchase review through ongoing oversight; carried out through the Cybersecurity Risk Management (06-107.1.2) and Personnel & Third-Party Security (06-107.1.3) Standards.